- Description
- IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client. IBM X-Force ID: 86138.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
CVSS 3.0
- Type
- Primary
- Base score
- 7.3
- Impact score
- 5.2
- Exploitability score
- 2.1
- Vector string
- CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 4.1
- Impact score
- 4.9
- Exploitability score
- 5.1
- Vector string
- AV:A/AC:L/Au:S/C:P/I:P/A:N
- nvd@nist.gov
- CWE-310
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:sterling_connect:3.4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0121DC25-B8D3-409F-B894-40CFB0C0DA42"
},
{
"criteria": "cpe:2.3:a:ibm:sterling_connect:3.4.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C57B819A-1D04-458E-87A2-0398A63FAB58"
},
{
"criteria": "cpe:2.3:a:ibm:sterling_connect:3.5.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBBB486E-5869-48F9-B9CE-733F9E167E19"
},
{
"criteria": "cpe:2.3:a:ibm:sterling_connect:3.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F92AD602-408F-433E-BE57-31A21313ACA5"
},
{
"criteria": "cpe:2.3:a:ibm:sterling_connect:3.6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15EE5C7B-A3DB-43DB-B2EE-4600C92A01D2"
}
],
"operator": "OR"
}
]
}
]